SC-400 Insider Risk Management 2 — Questions and Answers
Question 1: Which role is required to configure Insider Risk Management policies in Microsoft Purview?
- Compliance Administrator (Correct answer)
- Security Reader
- Global Reader
- Exchange Administrator
Correct answer: Compliance Administrator
The Compliance Administrator role (or Insider Risk Management role group) is required to create and manage Insider Risk Management policies.
Question 2: An organization wants to detect when employees are accessing sensitive data shortly before their scheduled departure date. Which Insider Risk Management policy template should be used?
- Departing employee data theft (Correct answer)
- Data leaks by priority users
- General data leaks
- Security policy violations
Correct answer: Departing employee data theft
The 'Departing employee data theft' template is specifically designed to detect risky activities by employees who have a termination date set in HR systems.
Question 3: What is the purpose of the 'sequence' feature in Insider Risk Management?
- It detects a series of related risk activities that together indicate a higher risk (Correct answer)
- It ranks alerts by severity score
- It sequences alert notifications to managers
- It orders cases by creation date
Correct answer: It detects a series of related risk activities that together indicate a higher risk
Sequences identify chains of related activities (e.g., browsing job sites, then exfiltrating files) that together represent a more significant insider threat.
Question 4: Which of the following is a prerequisite for using HR-based triggers in Insider Risk Management policies?
- Configure an HR data connector (Correct answer)
- Enable Microsoft Defender for Endpoint
- Set up a DLP policy first
- Enable audit logging in Exchange Online
Correct answer: Configure an HR data connector
The Microsoft 365 HR data connector must be configured to import termination dates and other HR signals used as policy triggers.
Question 5: A security analyst wants to review all content associated with a specific insider risk case. Which Insider Risk Management feature allows them to view actual file content?
- Content explorer in the case (Correct answer)
- Alert dashboard
- User activity report
- Policy analytics
Correct answer: Content explorer in the case
The content explorer within a case allows investigators with appropriate permissions to view the actual files and emails associated with a user's risky activity.
Question 6: What happens to an Insider Risk Management alert when it is 'dismissed'?
- The alert is closed without creating a case (Correct answer)
- The user's policy is permanently disabled
- The alert is escalated to a compliance manager
- The alert is archived for 90 days then deleted
Correct answer: The alert is closed without creating a case
Dismissing an alert closes it without escalating to a case, indicating the activity was reviewed and deemed non-actionable.
Question 7: Which Insider Risk Management setting controls how long user activity data is retained for policy evaluation?
- Policy timeframes (Correct answer)
- Retention policies
- Data retention labels
- Alert retention settings
Correct answer: Policy timeframes
Policy timeframes in Insider Risk Management settings define the activation and past activity detection windows for evaluating user activity.
Which role is required to configure Insider Risk Management policies in Microsoft Purview?